In effectSB 149 (2024); amended by SB 226, HB 452, SB 332 (2025) and HB 320 (2026)
Utah Artificial Intelligence Policy Act: Compliance Checklist
A practical checklist of the main obligations to satisfy under this law.
Compliance checklist
Run through these items to scope your obligations under Utah Artificial Intelligence Policy Act. Not legal advice; verify with counsel before acting.
- Confirm scope: does the law apply to your operations? See Who Must Comply or use the Compliance Checker.
- Inventory in-scope AI systems and classify them by role (developer/deployer) and decision type.
- Address each obligation:
- disclosure — A supplier using generative AI in a consumer transaction must disclose that the individual is interacting with generative AI and not a human when the individual makes a clear and unambiguous request about whether AI is being used; regulated-occupation providers must prominently disclose GenAI use for high-risk AI interactions, verbally at the start of verbal interactions or in writing before written interactions.Utah Code § 13-77-103
- governance — Maintain accountability for consumer-protection compliance when generative AI makes a violative statement, undertakes a violative act, or is used in furtherance of a violation; Chapter 77 states that generative AI is not a defense to statutes administered and enforced by the Division of Consumer Protection.Utah Code § 13-77-102
- data handling — Mental health chatbot suppliers may not sell or share individually identifiable health information or a Utah user's chatbot input with a third party, and must keep Chapter 72a privacy controls separate from the general Chapter 77 consumer-transaction disclosure rule.Utah Code § 13-72a-201
- disclosure — Mental health chatbot suppliers must clearly and conspicuously disclose that the chatbot is artificial intelligence technology and not human before features are accessed, at the beginning of an interaction after a seven-day gap, and whenever a Utah user asks or prompts about whether AI is being used.Utah Code § 13-72a-203
- Adopt a federal control framework: NIST AI RMF or ISO/IEC 42001 to demonstrate due care.
- Document evidence of compliance for each obligation, refreshed at the cadence the law requires.
- Build the AG-notification path if the law requires it (Colorado, California SB 53).
- Set the refresh cadence — annual for most impact-assessment regimes; continuous for monitoring.
We may receive referral commissions from recommended compliance tools. Recommendations are based on product fit and not on commission size. Links marked “partner link” include a tracked redirect.